Description

A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls command parameter parsing, triggered by a remote, authenticated attacker sending a crafted STAT command with a specific byte sequence.

INFO

Published Date :

2026-01-14T15:23:03.708Z

Last Modified :

2026-03-16T06:08:03.740Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2025-14242 vulnerability.

Vendors Products
Redhat
  • Enterprise Linux
  • Enterprise Linux Eus
  • Rhel Aus
  • Rhel E4s
  • Rhel Eus
  • Rhel Eus Long Life
  • Rhel Tus

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact